Governance, Risk and Responsible Use: CCAO-F domain 6 study guide
CCAO-F · Governance, Risk, and Responsible Use (15% of the exam)
Governance, Risk and Responsible Use is domain 6 of the Claude Certified Associate Foundations exam, 15% of the scored items. It tests whether you can tell a good use of Claude from a risky one, protect sensitive data before it reaches Claude, follow your organisation's AI policy, and keep people accountable for decisions that affect others.
What the official guide covers
The Claude Certified Associate Foundations exam guide (version 1.0, effective July 2026) lists four tasks under domain 6, Governance, Risk, and Responsible Use:
| What the guide lists | What it means in practice |
|---|---|
| Identify appropriate and inappropriate use cases | Know which tasks suit Claude, which need expert sign-off and which Claude should not do |
| Apply data sensitivity, regulatory and privacy considerations | Classify data before using it; remove or mask what policy restricts |
| Follow organisational AI policies and governance standards | Use approved accounts, tools and connectors; record and escalate as the policy says |
| Understand the ethical implications of AI usage | Consider bias, fairness, transparency and who is affected by the output |
Appropriate, needs sign-off, or not for Claude
| Use | Category | What makes it so |
|---|---|---|
| Drafting internal emails, summarising your own meeting notes | Appropriate with your own review | Low stakes, you know the source |
| Research summaries, first drafts of reports | Appropriate with fact-checking | Errors can be caught against sources |
| Customer-facing content, public statements | Needs owner sign-off | Errors reach people who act on them |
| Legal, financial, medical or regulatory content | Needs a qualified specialist's review | Claude does not replace professional judgement |
| Deciding who is hired, promoted, disciplined or refused a service | A person decides; Claude may only organise evidence | Decisions about people need human accountability |
| Content that deceives people or breaks law or company policy | Not appropriate | No review makes it acceptable |
Screening a new use case
Run four questions on any proposed use:
- Reversibility. If an output is wrong, can someone catch and reverse it before harm is done?
- Cost of error. What happens if it is wrong, and to whom?
- Human element. Does the task need empathy, relationship or creative judgement that should come from a person?
- Accountability. Who answers for the outcome, and can they really own an AI-produced result?
The questions interact, so name the one that decides the case: the criterion that, if it changed, would move the use into a different category. A client condolence note carries low risk and can be undone, yet the relationship means a person should write it. A financial summary is high stakes, yet acceptable once a named reviewer signs it off before use.
"Appropriate with review" needs a defined gate
This is the category most often got wrong. "A human stays in the loop" is not a gate. A gate names who reviews (the role that is accountable, not whoever is free), what they check (accuracy against the account record, fairness, policy), and when (before the output is used). Example: drafted replies to billing complaints are appropriate with review if a support agent checks each one against the customer's actual account, and adjusts the tone, before it is sent. A gate you cannot express in that form means the use is not ready.
Classify data before you use it
Decide what kind of data you hold before you paste, upload or connect it.
| Data class | Examples | What to do |
|---|---|---|
| Public | Published reports, press releases | Use freely |
| Internal | Team plans, process notes | Use in the company's approved Claude workspace |
| Confidential | Contracts, pricing, unreleased plans | Use only where policy allows, in the approved workspace |
| Personal or regulated | Customer names and contact details, employee records, health or financial details | Remove, mask or aggregate first unless policy explicitly permits use |
Techniques that let the work go ahead safely:
- Minimise. Share only the columns or passages the task needs.
- Mask. Replace names and identifiers with labels such as Customer A.
- Aggregate. Give totals by region instead of rows per customer.
- Use the approved place. A personal account is not the same as the company workspace, even for the same person.
If the data could fall in either of two classes, handle it as the more sensitive class until you confirm. Redaction has two failure modes. Partial redaction: strip the name but keep an account number, an unusual job title or an exact date, and a person in a small group can still be identified. Redaction that breaks the task: when the task really depends on the identifiers, masking is not the answer; confirm an approved route for that data or leave it out.
What the Claude apps do and do not control
- Work accounts belong to the organisation. On Team and Enterprise plans, the organisation's Primary Owner manages the account and its data, and can limit which features members use.
- Enterprise retention is set by owners. Owners on Enterprise plans can set how long conversation and project data is kept.
- Incognito is not a policy exception. Incognito chats are not saved to your chat history or to memory, but Anthropic still retains them for a period, and on Team and Enterprise plans they are included in the data exports available to owners. They are only available outside Projects. Incognito controls what is remembered; it does not answer whether the data was allowed there in the first place. For regulated data, settle that question first.
- Memory can be turned off for everyone on Enterprise. Enterprise owners can disable memory for the organisation; Team plan members manage their own memory settings.
- Connectors mirror permissions. Claude sees only what your account can already see in Google Workspace, and Gmail send, reply and forward actions ask for your approval by default. On Team and Enterprise plans, an Owner must enable these connectors before members can use them.
Treat a Skill like software you are about to install
A Skill is a folder of instructions and often scripts that Claude runs. Anthropic's help centre names prompt injection and data exfiltration as the main risks, and advises installing Skills only from trusted sources and auditing a less-trusted Skill's files first. Three checks:
| Check | Question |
|---|---|
| Source | Who published it? Anthropic Skills and ones your organisation provisioned are the safer start |
| Reach | What could it touch in the chats where it will run, and is that in proportion to the job? A formatting Skill whose instructions go far beyond formatting is a warning sign |
| Fit | Is it the right tool, or more capability than the task needs? |
The outcome is enable (all three clear), escalate to your admin or security team (useful, but the source is unclear or the reach looks broad), or decline (clearly out of proportion). A Skill from another team, or one a colleague found and recommends, is not vetted until someone checks what it touches. Switch on only the connectors a task needs.
Pre-use checklist
BEFORE USING CLAUDE ON THIS TASK
[ ] Is this use allowed by our AI policy? (If unsure, ask the policy owner.)
[ ] Am I in the approved company workspace, not a personal account?
[ ] What is the most sensitive data involved? Public / internal /
confidential / personal or regulated
[ ] Have I removed, masked or aggregated anything policy restricts?
[ ] Are the connectors I have switched on approved and needed?
[ ] Who could be affected by the output, and could it treat any group
unfairly?
[ ] Who reviews the output, and who owns the final decision?
[ ] Does our policy require me to say that AI helped produce this?
The ethical questions to ask
| Question | Why it matters | What to do |
|---|---|---|
| Could the output be biased? | Claude can reflect one-sided sources or framing | Check who is missing; review who an automated screen drops, not only who it keeps |
| Who is accountable? | Claude cannot take responsibility | Name the person who approves and owns the result |
| Are people told AI was used? | Readers may rely on it differently | Follow your organisation's disclosure rules |
| Is anyone relying on it too much? | Over-reliance lets errors through | Keep review steps even when results look good |
| Does it affect a person's rights or livelihood? | The cost of an error is high | Keep a person as the decision maker |
For a case no rule settles, note the people affected, the possible harms, what fairness would look like, and the disclosure the setting needs. When unsure about disclosure, disclose. If many people are affected or the harm could be serious, take your written reasoning to your AI governance or ethics function rather than deciding alone.
Policy also drifts in practice. Periodically compare what your team does with the policy: an unapproved upload, a Skill enabled without a check, a review gate skipped under deadline pressure.
When to escalate
Escalate to your AI policy owner, privacy or legal team when you are unsure whether data or a use is allowed, and to Claude Architects or Developers when a task needs custom integrations, automation at scale or technical controls.
Rules that decide exam answers
- Fix the data, then do the task. When personal data is restricted, the best answer removes or masks it and carries on; uploading as-is and abandoning the work are both wrong.
- Telling Claude to forget is not a control. Instructions to Claude, incognito chats and good intentions do not replace the data rules in your policy.
- Use the approved workspace. Company data belongs in the company's Claude account, not a personal one.
- People decide about people. Claude can organise evidence for a hiring or performance decision; it does not make the decision.
- Fix the friction behind a workaround. If staff use personal accounts because the approved workspace is slower, the organisation owns that gap: make the approved route the easy one.
- When the policy is unclear, ask. Escalating to the policy owner beats both guessing and refusing to use Claude at all.
Where it appears in the exam
Domain 6 carries 15% of the exam, around 9 of the 60 items. Questions describe a task with a risk in it, such as personal data, a decision about people, a request outside policy or content that could be unfair, and ask for the most appropriate action.
Two sample questions
These are original Timo practice questions. They are not official exam questions.
Build exercise
- Find your organisation's AI policy. List what it says about approved tools, data classes, disclosure and escalation.
- Take a real dataset you would like Claude to analyse. Classify each column, then mask or remove what the policy restricts.
- Run the pre-use checklist on three tasks you did with Claude this month. Note any you would now handle differently.
- Write a one-paragraph escalation note for a use case where the policy is unclear, addressed to your policy owner.
Practise this topic
- Claude Certified Associate practice exam: free, 20 questions, no sign-up
- CCAO-F study guide: all topics
- Same topic in another exam: 5.5 Human review and confidence (CCAR-F) and Governance, Safety and Risk (CCAR-P)
- Previous topic: Configuration and Knowledge Management
- Next topic: Troubleshooting and Optimization
Sources
- Claude Certified Associate Foundations Exam Guide, version 1.0, effective July 2026 (Anthropic), domain 6: Governance, Risk, and Responsible Use
- Claude Help Center: Use incognito chats
- Claude Help Center: Who owns and manages the data of my team?
- Claude Help Center: Configure custom data retention controls for Enterprise plans
- Claude Help Center: Use Google Workspace connectors
By Amotion AI